🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 104.248.194.193:80.

Database Entry


IOC ID:1932259
IOC: 104.248.194.193:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-09-24 12:56:33 UTC
Last seen:never
UUID:cc1cd140-b816-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:Amos cc2 ClickFix Foxveil macOS
Reference: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9

Avatar
c4ffeine
Foxveil/AMOS telemetry and exfil backend, DigitalOcean 104.248.0.0/16, plain HTTP on port 80, no TLS listener. Named in the decoded AMOS AppleScript payload of Foxveil cc2 build 28 (blueprint-71.com, built 2026-09-22) and every opened build up to cc2 build 47 and DANTE build 6 (journeylake11.com, 2026-09-23 22:03 UTC), in the slot 165.232.73.74 held before it and 206.189.104.97 (ThreatFox 1931224) holds since 2026-09-23 23:01 UTC. Body-confirmed via Tor 2026-09-22: GET /contact and GET /api/metrics/run answer the forged 139 B 404 (sha256 5d1d75b702f13e1bb14ff8d52cac1690acacec3a15821af7fe482a79afda5b99) that every Foxveil backend serves; / gets the stock 146 B nginx 404. Never POSTed. The stealer POSTs victim data to /contact and run telemetry to /api/metrics/run. Sample: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9